Press "Enter" to skip to content

OSINT / CyberSec report 11.07.2026 00:07

1. Attackers are exploiting the Ill Bloom vulnerability in cryptocurrency wallet software to drain funds by predicting recovery phrases generated with weak randomness (thehackernews.com).

2. A former ransomware negotiator was sentenced to 70 months in prison for conspiring with the BlackCat ransomware group to extort victims (thehackernews.com).

3. The new GodDamn ransomware family is using the PoisonX kernel driver to disable endpoint security software (thehackernews.com).

4. Microsoft patched the RoguePlanet vulnerability, tracked as CVE-2026-50656, which allowed attackers to gain SYSTEM privileges via the Windows Malware Protection Engine (thehackernews.com).

5. A new data extortion group named Helix is targeting SharePoint environments using voice phishing and MFA abuse (bleepingcomputer.com).

6. The Forg365 phishing as a service platform is using AI to generate lures and steal Microsoft 365 account credentials (bleepingcomputer.com).

7. Hackers compromised the Injective Labs SDK on npm to distribute a malicious package that steals cryptocurrency wallet keys (bleepingcomputer.com).

8. A network of 200 GitHub repositories was identified as being used for malware distribution (reddit.com).

9. The ModHeader browser extension was removed from stores after being found to contain malware, impacting 1.6 million installs (reddit.com).

10. Attackers are using HalluSquatting techniques to turn AI hallucinations into a delivery mechanism for botnets (reddit.com).

11. Datadog Security Labs reported that attackers are using dormant GitHub accounts and compromised OAuth tokens to map corporate organizations (thehackernews.com).

12. A Puerto Rico government agency suffered a data breach exposing 1 million social security numbers (reddit.com).

13. The OpenMandriva Linux project reported an attempted act of internal sabotage by a contributor (bleepingcomputer.com).

14. Latvijas Valsts Mezi, a state owned forestry company in Latvia, is still restoring systems following a ransomware attack (therecord.media).

15. Microsoft released GigaWiper, a destructive backdoor that combines disk wiping, fake ransomware, and spyware capabilities (thehackernews.com).

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *